Skip to content

Releases: mcpg-dev/mcpg-inspector

v0.1.0-beta.43

v0.1.0-beta.43 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 29 Sep 00:03

Release of mcpg-inspector at v0.1.0-beta.43.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.43" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.43 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.41

v0.1.0-beta.41 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 26 Sep 05:19

Release of mcpg-inspector at v0.1.0-beta.41.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.41" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.41 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.40

v0.1.0-beta.40 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 25 Sep 07:19

Release of mcpg-inspector at v0.1.0-beta.40.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.40" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.40 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.39

v0.1.0-beta.39 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 24 Sep 20:26

Release of mcpg-inspector at v0.1.0-beta.39.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.39" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.39 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.33

v0.1.0-beta.33 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 21 Sep 02:39

Release of mcpg-inspector at v0.1.0-beta.33.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.33" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.33 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.32

v0.1.0-beta.32 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 20 Sep 23:39

Release of mcpg-inspector at v0.1.0-beta.32.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.32" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.32 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.31

v0.1.0-beta.31 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 19 Sep 03:24

Release of mcpg-inspector at v0.1.0-beta.31.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.31" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.31 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.30

v0.1.0-beta.30 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 18 Sep 21:50

Release of mcpg-inspector at v0.1.0-beta.30.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.30" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.30 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.29

v0.1.0-beta.29 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 14 Sep 04:49

Release of mcpg-inspector at v0.1.0-beta.29.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.29" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.29 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>

v0.1.0-beta.28

v0.1.0-beta.28 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 14 Sep 00:50

Release of mcpg-inspector at v0.1.0-beta.28.
Issues are welcome; pull requests cannot be merged here — development happens upstream.

This crate is consumed by git reference — it is not published to crates.io:

[dependencies]
mcpg-inspector = { git = "https://github.com/mcpg-dev/mcpg-inspector", tag = "v0.1.0-beta.28" }

(binaries: cargo install --git https://github.com/mcpg-dev/mcpg-inspector --tag v0.1.0-beta.28 mcpg-inspector, or use the packed assets below)

Every asset is signed with cosign (keyless, Sigstore transparency log);
public releases also carry a SLSA build-provenance attestation. Verify one with:

gh attestation verify <file> --repo mcpg-dev/mcpg-inspector

A resolved Cargo.lock and an SPDX SBOM are attached. Every lane built --locked against that exact
lockfile, so it describes these binaries rather than a later resolution — to rebuild this version
byte-for-byte, drop it in as Cargo.lock and build --locked.
Library and plugin releases also carry a cargo-public-api diff of the public Rust surface against the
previous release tag — these releases do not ship a changelog, and that diff is the machine-checkable
answer to what changed.

macOS: the aarch64-apple-darwin binaries are signed by cosign but are not Apple-codesigned or
notarised, so Gatekeeper quarantines them on download and reports the binary as damaged. That is a policy
decision by macOS, not a corrupt artifact — verify the cosign signature, then clear the quarantine flag:

xattr -d com.apple.quarantine ./<binary>